Re: PHP 5.6.40 on Jessie

2019-01-30 Thread Markus Koschany
Hello, Am 30.01.19 um 15:56 schrieb Jean-Baptiste Martin-Ariès: > Hello, > > PHP 5.6.40 had been made available on 10 Jan 2019 and contains several > bugs and security fixes.  > > Is it planned to package it for Jessie ? When the package should be > available ? Yes, we will package 5.6.40. Appa

PHP 5.6.40 on Jessie

2019-01-30 Thread Jean-Baptiste Martin-Ariès
Hello, PHP 5.6.40 had been made available on 10 Jan 2019 and contains several bugs and security fixes. Is it planned to package it for Jessie ? When the package should be available ? JB

Re: RFC / Call for testing: ghostscript

2019-01-30 Thread Markus Koschany
[No need to CC me, I am subscribed] Am 30.01.19 um 14:29 schrieb Moritz Mühlenhoff: > On Wed, Jan 30, 2019 at 01:24:40PM +0100, Markus Koschany wrote: >> Hi, >> >> Am 30.01.19 um 13:07 schrieb Emilio Pozuelo Monfort: >> [...] >>> I would appreciate some testing and/or feedback. >> >> I have done m

Re: RFC / Call for testing: ghostscript

2019-01-30 Thread Moritz Mühlenhoff
On Wed, Jan 30, 2019 at 01:24:40PM +0100, Markus Koschany wrote: > Hi, > > Am 30.01.19 um 13:07 schrieb Emilio Pozuelo Monfort: > [...] > > I would appreciate some testing and/or feedback. > > I have done most of the backporting work for the previous > vulnerabilities of Ghostscript. I don't reco

Re: RFC / Call for testing: ghostscript

2019-01-30 Thread Markus Koschany
Hi, Am 30.01.19 um 13:07 schrieb Emilio Pozuelo Monfort: [...] > I would appreciate some testing and/or feedback. I have done most of the backporting work for the previous vulnerabilities of Ghostscript. I don't recommend to backport the stable version to Jessie at the moment but rather to contin

RFC / Call for testing: ghostscript

2019-01-30 Thread Emilio Pozuelo Monfort
Hi, There is a vulnerability in ghostscript that allows maliciously crafted files to bypass the sandbox and execute arbitrary code: https://bugs.chromium.org/p/project-zero/issues/detail?id=1729 I would be wary of backporting the fix to our old version of ghostscript as the code has changed quit